CVE-2025-60010: medium-severity vulnerability in Juniper Networks Junos OS
Junos OS and Junos OS Evolved: Device allows login for user with expired password
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change.
Affected devices allow logins by users for whom the RADIUS server has responded with a reject and required the user to change the password as their password was expired. Therefore the policy mandating the password change is not enforced.
This does not allow users to login with a wrong password, but only with the correct but expired one.
This issue affects:
Junos OS:
* all versions before 22.4R3-S8,
* 23.2 versions before 23.2R2-S4,
* 23.4 versions before 23.4R2-S5,
* 24.2 versions before 24.2R2-S1,
* 24.4 versions before 24.4R1-S3, 24.4R2;
Junos OS Evolved:
* all versions before 22.4R3-S8-EVO,
* 23.2 versions before 23.2R2-S4-EVO,
* 23.4 versions before 23.4R2-S5-EVO,
* 24.2 versions before 24.2R2-S1-EVO,
* 24.4 versions before 24.4R1-S3-EVO, 24.4R2-EVO.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/RE:M
Related CVEs — Juniper Networks Junos OS
In the same product, most dangerous first.
CVE-2023-36845CRITICALJunos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variableEPSS 95.1%KEVCVE-2023-36846MEDIUMJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 93.5%KEVCVE-2023-36844MEDIUMJunos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variablesEPSS 90.0%KEVCVE-2023-36847MEDIUMJunos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 83.5%KEVCVE-2020-1631HIGHOut of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) servicesEPSS 4.8%KEVCVE-2025-21590MEDIUMJunos OS: An local attacker with shell access can execute arbitrary codeEPSS 1.7%KEV